The Transparency Paradox: How States Are Restricting Access to License Plate Reader Data
Introduction
Automated license plate readers (ALPRs) have become a widespread surveillance tool, capturing the time, location, and movement of millions of vehicles daily. For years, journalists, civil rights advocates, and organizations like the Electronic Frontier Foundation (EFF) have used public records laws—such as Freedom of Information Acts (FOIAs) and Public Records Acts (PRAs)—to uncover misuse, fraud, and overreach in police ALPR programs. These disclosures have revealed troubling patterns: data shared across agencies without oversight, false hits leading to unwarranted stops, and long retention periods that create detailed travel profiles. Now, a backlash is brewing: state legislatures are moving to block public access to this very information, citing privacy concerns. But in doing so, they risk silencing the very oversight that keeps surveillance accountable.

Public Records as a Check on Surveillance
Every state grants citizens the right to obtain government records. These laws are a cornerstone of democratic accountability, allowing the public to see how their tax dollars are spent and how their rights are respected. When applied to ALPR systems, these requests have yielded eye-opening insights:
- Scale of use: How many cameras are deployed, and in which neighborhoods?
- Data sharing: Which agencies (local police, state patrol, federal partners) receive or contribute to ALPR databases?
- Accuracy: How often do so-called 'hits' occur, and how many are false positives that lead to mistaken stops?
- Retention policies: How long is raw scan data kept, and who can query it?
This public oversight has directly led to reforms, such as deletion policies and bans on warrantless queries. Without it, many ALPR programs would operate in the dark.
States Slam the Door on Transparency
In response to these disclosures, lawmakers in several states have passed or are considering bills that explicitly exempt ALPR data from public records laws. Arizona and Connecticut are currently debating proposals that would broadly block access not only to raw scan data but also to derived information—such as aggregate usage statistics or analysis of hit rates. EFF has voiced strong opposition to these measures, arguing that they go far beyond protecting legitimate privacy interests.
These bills often frame themselves as privacy protections, but they fail to differentiate between sensitive personal data and systemic oversight information. A reporter asking for the number of scans conducted in a low-income neighborhood shouldn't be denied because that number is 'derived' from ALPR data. Yet that is precisely the chilling effect of these broad exemptions.
Privacy vs. Transparency: The False Choice
To be fair, releasing raw ALPR data—such as a database of everyone's license plate scans over months—would indeed create severe privacy risks. It would allow anyone (including stalkers, journalists, or political opponents) to track individuals' movements. The EFF has consistently opposed such wholesale disclosure precisely because it amplifies the harms of surveillance.
But the current proposals don't seek a middle ground. They create an outright ban on disclosure, even for data that doesn't identify individuals. For example, information about how many times a camera mistakenly reads a plate (a false positive rate) is crucial for evaluating the system's reliability. Blocking that is not privacy protection—it's secrecy.

A Balanced Approach: Transparency with Privacy
A better legislative path exists. Lawmakers can design exemptions that protect identifiable personal data while preserving access to aggregate and policy-relevant records. Key principles include:
- Identify sensitive vs. non-sensitive data: Raw scans linked to a specific plate should be confidential unless needed for a criminal investigation. But aggregate counts, error rates, sharing agreements, and procurement records should remain public.
- Limit derived data exemptions: If a statistic is derived from ALPR data but does not reveal an individual's location (e.g., total scans per month), it should not be blocked.
- Require transparency reports: Agencies should publish annual summaries of ALPR usage, including retention periods, hit rates, and audit logs, so the public doesn't have to file FOIA requests for basic information.
This approach respects privacy while ensuring that the public can verify the claims made by law enforcement about the effectiveness and fairness of ALPR systems.
EFF's Position: Don't Cut Off Oversight
The EFF has long opposed ALPRs because of the intrusive nature of mass location tracking. But even as we advocate for banning or strictly limiting their use, we recognize that until that happens, oversight is essential. Blocking public records access does not make ALPRs less harmful—it makes them less accountable. The EFF supports carefully tailored privacy protections within public records laws, but not broad exemptions that shield police from scrutiny.
As more states rush to enact these restrictions, the public risks losing its most powerful tool for understanding how surveillance affects communities. The solution is not to hide the data, but to ensure that disclosure is done in a way that respects individuals' privacy while holding power to account.
Conclusion
The debate over ALPR data access is a microcosm of a larger tension in a surveillance-rich world: how much should the public know about the systems watching them? Blanket exemptions are a blunt instrument that harms oversight without truly protecting privacy. By crafting nuanced rules that distinguish between sensitive personal data and systemic information, states can preserve the transparency that FOIAs were designed to provide—while still respecting the legitimate privacy interests of their citizens.